smartnuts … the world on the cabaret-style dissecting table

Porsche Macan is falling behind UN R155 Requirements

P

A slightly fuzzy article that has been put together here by Golem.1 Perhaps briefly summarized:

The electrical/electronic system (E/E system) of a vehicle, which had its SOP (start of production) for the first time in 2013, has not been further developed for 10 years and now falls behind the requirements for automotive cybersecurity with the entry into force of UN-R155 rules for so-called „All Types“.

Hmm – doesn’t sound so bad at first – how should one already know the regulatory requirements at the time of the development of the E/E system (usually 5-6 years before the SOP of the vehicles equipped with this E/E system) and take them into account in the design?

On the other hand, we are not talking about requirements that originate from rocket science: Protection of ECUs against unauthorized root access, integrity protection of software on ECUs, reasonable vulnerability management process … All these things were already state of the art at the time of the design of the E/E-system or could at least have been added during the life of the vehicle in the field.

In this respect, the vehicle was probably designed more as a cash cow that could be milked until the last day and then pushed into the cover pit. Other manufacturers can do better … 🙂

  1. Link: https://www.golem.de/news/porsche-eu-verkaufsstopp-fuer-macan-wegen-cybersicherheit-2312-180343.html ↩︎

About the author

Michael Bunzel

Michael (Mike) Bunzel (aka maschasan) is a lawyer and engineer currently living in Germany. He has been working in the field of Cybersecurity and related laws and regulations for over 25 years now.

Mike took on various roles and functions in the context of Information Security, Cybersecurity, and SCADA/Shopfloor Security at a German car manufacturer in southern Germany for more than fifteen years now - currently in the R&D resort, with focus on E/E-systems in the context of automotive cybersecurity.

Mike has worked with global organizations across dozens of countries, cultures and languages, well-travelled in EMEIA, APAC and the Americas.

All articles in this blog do NOT reflect the opinion of his employer, but are all an expression of his personal view of things.

By Michael Bunzel
smartnuts … the world on the cabaret-style dissecting table

Get in touch

Tags